All Products
Search
Document Center

Security Center:CreateOrUpdateDingTalk

Last Updated:Aug 28, 2026

Creates or updates a DingTalk chatbot notification configuration.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:CreateOrUpdateDingTalk

create

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Id

integer

No

The ID of the chatbot.

Note

Call DescribeDingTalk to query chatbot IDs.

1589

RuleActionName

string

Yes

The name of the chatbot.

Note

Must be 2 to 64 characters.

testNotify

SendUrl

string

Yes

The webhook URL.

https://oapi.dingtalk.com/robot/send?access_token=XXX

IntervalTime

integer

No

The notification interval.

Note

0 indicates no limit.

0

ConfigList

string

No

Alert notification settings. JSON array with the following fields:

  • type: alert type. See the additional parameter descriptions below.

  • configItemList: check items. JSON array with the following fields:

    • key: check item key.

    • valueList: check item values. JSON array.

Note

See the additional parameter descriptions below.

[{"type":"sas_analysis_online-sas-operation-log-sas-event-suspicious","configItemList":[{"key":"item_level","valueList":["all"]},{"key":"event_type","valueList":["all"]}]}]

GroupIdList

string

No

Asset group IDs for notification targeting. JSON array.

Note

Call DescribeGroupStruct to query asset group IDs.

["10417151"]

DingTalkLang

string

No

Notification language. Valid values:

  • zh: Chinese

  • en: English

zh

Additional description of parameters

type Description key Description valueList Description
sas_analysis_online-sas-operation-log-sas-event-vul Vulnerabilities type Vulnerability type all All
cms Web-CMS vulnerability
oval Linux software vulnerability
sys Windows system vulnerability
emg Urgent vulnerability
necessity Risk level all All
asap High
later Medium
nntf Low
sas_analysis_online-sas-operation-log-sas-event-hc Baseline risks item_level Risk level all All
high High
medium Medium
low Low
sas_analysis_online-sas-operation-log-sas-event-suspicious Alerts item_level Severity all All
serious Critical
suspicious Suspicious
remind Remind
event_type Alert type
all All
Suspicious process Suspicious process
Webshell Webshell
Unusual logon Unusual logon
Exception Exception
Sensitive file tampering Sensitive file tampering
Malicious process (cloud threat detection) Malicious process (cloud threat detection)
Unusual network connection Unusual network connection
Others Others
Abnormal account Abnormal account
Application intrusion event Application intrusion event
Cloud threat detection Cloud threat detection
Precision defense Precision defense
Application whitelist Application whitelist
Persistent webshell Persistent webshell
sas_analysis_online-sas-operation-log-sas-event-ak-leakage AccessKey pair leaks type Leak type all All
sas_analysis_online-sas-operation-log-sas-event-honeypot Alerts generated by cloud honeypot item_level Risk level all All
high High
medium Medium
low Low
sas_analysis_online-sas-operation-log-sas-event-rasp Alerts generated by application protection item_level Risk level all All
high High
medium Medium
low Low

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID.

76975B7A-34DC-5CB6-9538-91700D4F112E

Examples

Success response

JSON format

{
  "RequestId": "76975B7A-34DC-5CB6-9538-91700D4F112E"
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.